The challenge behind the engagement.
Internal network penetration testing measures how far an attacker moves once inside. We start from a position you choose: a shipped device on your network, remote access, a low-privilege account, or no credentials at all. From there we map the hosts, shared resources, and services within reach. Then we work the paths that turn one foothold into broad access by hand: harvesting and reusing credentials, abusing misconfigured sign-in and directory services, intercepting weak network authentication, and abusing trust between systems. The paths fit your environment, whether an on-premises directory, a cloud identity platform, or both. We move sideways, escalate toward high-value accounts, and check separation into sensitive systems. You receive an attack-path narrative from foothold to objective, an identity attack-path diagram, segmentation results, and a retest after remediation.
For teams whose internal network and identity systems could be reached by a phished employee or a rogue insider, and who want that blast radius measured. Often bought after an external test, before a segmentation audit, or following a ransomware scare.
What we do.
What you can use.
Set the starting position
We agree the foothold: a shipped device on your network, remote access, a standard-user account for an assumed-breach start, or no credentials at all. You confirm network reachability to the target segments, name a stop contact, and decide whether your detection and response are measured or bypassed for this run.
Work the attack paths
We map hosts and shared resources, then chase the paths that widen access by hand: cracking and reusing exposed credentials, abusing misconfigured sign-in and directory services, and intercepting weak network authentication where it is exposed. We escalate toward high-value accounts, using paths suited to an on-premises directory, a cloud identity platform, or a hybrid of both.
Map and retest
You receive an attack-path narrative from foothold to objective, an identity attack-path diagram, and segmentation results showing which zones held. Findings carry severity ratings and fixes written for the owner, and we retest remediated items with evidence.
Who it’s for.
When you need it.
- Organizations with a corporate network where a phished user could reach sensitive systems
- Teams running centralized identity and directory services across on-premises, cloud, or hybrid estates
- Businesses that must prove internal segmentation between user, server, and regulated zones
- Security owners who have tested the perimeter and now want insider-level assurance
- A phishing incident or ransomware scare raised questions about internal blast radius
- A segmentation audit or PCI DSS internal testing requirement is approaching
- An external test is complete and leadership wants to know what a foothold reaches
- A merger, office move, or network redesign changed internal trust relationships
What the scope can include.
- 01
Map hosts, shared resources, and services reachable from the agreed foothold
- 02
Abuse sign-in and directory services through credential and trust attacks
- 03
Harvest and reuse credentials to move sideways across the estate
- 04
Escalate privileges toward high-value administrative accounts where paths exist
- 05
Test segmentation between network segments and into cardholder or otherwise sensitive zones
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One office, up to about 100 computers and servers, one user directory
About 24–36 hoursTwo or three sites, up to about 500 computers and servers, office and cloud sign-in
About 40–64 hoursMany sites or 500 to 2,500 computers, several directories, segmented sensitive zones
About 72–120 hours- Number of computers, servers, and network segments in reach
- Number of sites and whether on-site work is needed
- How many user directories and sign-in systems are in play
- Segmentation checks between regulated or sensitive zones
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Attack-path narrative tracing the foothold to high-value administrative access
- Identity and directory attack-path diagram with per-zone segmentation results
- Credential and privilege findings with severity ratings and fixes for the identity team
- Retest confirming that remediated internal findings are closed
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Do you start with credentials or from scratch?
Either. The most common model is assumed breach, where you give us a standard-user account and network access so the engagement is spent on attack paths rather than on getting a first foothold. We can also start with no credentials to model an attacker who has just plugged in. We agree the starting position in writing during scoping.
Will you lock out accounts or disrupt our identity systems?
We tune activity to avoid it. Password attacks stay within the lockout limits we agree, and we schedule the noisier network techniques to protect availability. We run nothing destructive: we do not delete accounts or alter production configuration. You hold a stop contact, and we pause immediately on any sign of disruption to services or users.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
